The AI Agent Skill That Points at a Scam
When placeholder domains stop being placeholder
For years, developers have written yoursite.com, your-domain.com, and third-party.com into READMEs, tutorials, and configuration examples as stand-ins for real endpoints. They were meant as harmless filler — pointers the reader would edit to fit their own environment. Nobody registered them, because nobody had to.
Two of them are now registered. And they are serving scams.
This week, Manifold Security published two findings that turn those quiet stand-ins into an urgent problem for anyone shipping AI agents. In Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content (Sept 24, 2026) and Placeholder Domains Whose Ads Serve Scams (Sept 24), researcher Cody Nash documents that the placeholders have been quietly bought up, and the ads and JavaScript now running on them redirect visitors into fraud chains.
The numbers, and where they land
Manifold's corpus tells the story in blunt figures:
- Over 350,000 GitHub files reference
yoursite.comoryour-domain.com(185k and 174k respectively, per Manifold's Table 1). - 1,700+ repositories reference
third-party.com, per The Hacker News. - 349 AI agent skills in Manifold's corpus reference one of the two active-scam placeholders (143 for
yoursite.com, 206 foryour-domain.com). - 13 additional commonly-used placeholder domains are not IANA-reserved, which means anyone can buy them next.
- Affected repositories include high-profile projects such as
audreyfeldroy/favicon-cheat-sheet(9,909 stars per Manifold's Table 2).
The AI agent skills line is the one that matters most for the ecosystem we work in. A "skill" is a small file — Markdown, YAML, or JSON — that an AI coding agent reads into its context to learn how to perform a task. It's documentation the agent is going to follow. When 349 of those files point the agent at a URL that used to be a placeholder and is now a scam page, the agent has no reason to distrust the reference. It follows it.
The mechanic is a sequence
The classic wisdom on scanning code for suspicious URLs assumes a static crawler can see what a real browser sees. Manifold's finding closes that gap. Per the Sept 24 Manifold post, static checks against the 13 unreserved placeholder domains all came back clean; the malicious payload only fires after JavaScript runs in a real browser. Manifold reports that across sixteen macOS renders of the two active-scam domains, two ended on a scam page.
The observed lures:
yoursite.com— a counterfeit ZDFheute article oneuropaeinblick[.]click, built around a talk-show confrontation that never happened, advertising an investment scheme (per Manifold).your-domain.com— either a counterfeit BBC News "Question Time" article onfinanceprotips[.]siteadvertising the same investment scheme, or a fake "MacOS Security Center" claiming four viruses and selling a counterfeit McAfee renewal (per Manifold).third-party.com— for Windows visitors, a fake Cloudflare verification screen that hijacks the clipboard and instructs the user to paste a PowerShell command into the Run dialog. macOS visitors see "macOS is not supported. This website requires a Windows PC to access." (per The Hacker News, citing Manifold, which reports the ClickFix lure has been active since at least June 2026.)
What this changes for AI agent supply chains
Two things follow from the finding, and both matter for defenders.
Skill files are supply chain. The industry has spent the last year hardening the story around malicious packages on npm and PyPI, worms like Shai-Hulud, and compromised AI-agent-memory plugins like the MemTensor sckit credential stealer disclosed on Sept 23. Manifold's finding widens the surface one layer further out: the substrate isn't only the installed package, it's the string in the agent's context window. A URL in a skill file is an instruction the agent will follow. If the URL is compromised, the agent is too.
Static checks alone are not enough. All thirteen unreserved placeholder domains came back clean under Manifold's static analysis. The malicious behavior lives inside JavaScript that only executes when a real browser (or a real agent doing what a browser does) renders the page. Any control that stops at "does the string match a known-bad list" will miss this class of failure entirely.
The take-home for teams shipping agents
Manifold's own recommendation is the practical one: "Stop citing domains you do not control in documentation an agent will read." Use the IANA-reserved example.com, example.org, or example.net. Audit skill files, configuration examples, and READMEs for any of the 13 named placeholders and replace them.
Beyond that, the finding is a reminder of a longer trend the digest has been tracking all month. The boundary that has to be enforced for AI agents is not just at the package registry, and not just at the model. It's at the point where the agent is about to do something — fetch a URL, run a command, spend a credential — based on a string that was handed to it. That boundary has to be checked from outside the agent's own reasoning.
SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.